Analytics BIOC
Informational
✕
Abnormal User Login to Domain Controller
A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts (T1078) Use Alternate Authentication Material (T1550)
Attacker's goals:
A malicious user may attempt to access a domain controller to access and control Active Directory.
Investigative actions:
Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller. Check if the user is a service account that accesses a domain controller as part of its normal behavior. Verify that the user is not authenticating to group policy.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Rare RDP User Login to Domain Controller by an Abnormal Department Medium (parent: Informational)
- Abnormal RDP User Login to Domain Controller Low (parent: Informational)
- RDP User Login to Domain Controller Informational
- Abnormal User Login to Domain Controller by an Abnormal Department Informational